Skip to main content

Legal · Version 1.3 · Effective 30 September 2026

Cookie & Local-Storage Notice

Summa uses only technologies necessary to provide, secure and remember the service, plus one optional advertising pixel from X that runs only with your consent.

1. Current approach

Summa uses only cookies or browser storage necessary to provide, secure and remember the service, with one optional exception: the X (Twitter) advertising pixel described in section 4, which runs only if you accept it.

2. Necessary technologies

NameTypePurposeDuration
authjs.session-tokenCookieKeeps you signed in and protects the session12 hours
authjs.csrf-tokenCookiePrevents request forgerySession
authjs.callback-url, authjs.state, authjs.pkce.code_verifierCookiesComplete a secure sign-in exchangeShort-lived
auth_flowCookieCarries sign-in, two-factor and password-reset stepsShort-lived
active_tenant_idCookieRemembers which workspace you selected30 days
NEXT_LOCALECookie and local storageRemembers your chosen language1 year
sidebar_stateCookieRemembers whether the chat history panel is open7 days
summa-chat-tabs:<account>Local storageRemembers which chats you keep open as tabs, per account on this deviceUntil cleared
react-resizable-panels:summa-chat-layout…Local storageRemembers how wide you made the panel beside a chatUntil cleared
summa-themeLocal storageRemembers light or dark appearanceUntil cleared
summa_tracking_consentCookieRemembers whether you accepted or rejected the optional X pixel6 months

Language, the chat layout and tabs, appearance and your answer about the X pixel each remember a choice you made yourself. None of these technologies is used for advertising, profiling or cross-site tracking, and none is shared with a third party.

3. Website statistics

We measure how the public website is used so we can see which pages are useful and whether the site performs well. This measurement uses no cookies and stores nothing on your device, which is why you are not asked for consent for it: the rules on consent govern access to your device, and we do not access it.

Instead, when you open a page our own servers record that page, the response status, the referring website's domain name, and a coarse description of your device, browser and operating system. Your IP address is used only to derive a short-lived visitor code and is never stored. That code is produced with a secret key which is replaced and destroyed every day, so visits cannot be linked from one day to the next — by us or by anyone else. There is no profile, no advertising use, and no third party involved.

Once a page has loaded, moving to another page of the site usually happens without a new page request our servers could tell apart from the browser preparing a link in advance. So our own page code tells our servers which page you moved to, and it is recorded in the same way, under the same daily visitor code. Pages the browser only prepares in advance, without you opening them, are not recorded. This too stores nothing on your device.

On the public pages, our own page code also reports which links and buttons you click: the page you were on, the fixed name we gave the button, and where a link leads — a page on our site, or only the domain name of another site. It is sent to our servers under the same daily visitor code and nothing else. It never records what you type, the text on the screen, mouse movements or scrolling, and it stores nothing on your device.

If the link you arrived by carries campaign labels — the utm_… tags an advertiser adds to an ad or newsletter link — we record those labels. If it carries an advertising platform’s own click identifier instead, we record only which platform it came from, never the identifier. If an account is created during that visit, we record that an account was created, under the same daily visitor code and with nothing that identifies the account, so we can see which campaigns bring sign-ups. Every other part of a link’s address is discarded.

What we recordWhyHow long
Requested page and response statusSee which pages are used and which are failingUp to 90 days
Links and buttons you click, by their fixed name or destinationSee which buttons and links on the site are usedUp to 90 days
Campaign labels of the link you arrived bySee which campaigns bring visitorsUp to 90 days
That an account was created in the same visitSee which campaigns bring sign-upsUp to 90 days; never linked to the account
Referring website domainUnderstand where visitors come fromUp to 90 days
Device, browser and operating system categoryEnsure the site works on real devicesUp to 90 days
Daily visitor code derived from IP addressCount visitors and visits without identifying anyoneUp to 90 days; the key is destroyed daily
Page performance measurementsDetect slow pages for real visitorsUp to 90 days

After 90 days the detailed records are deleted and only daily totals remain. Because no stored value can be linked back to a person once the daily key is destroyed, these statistics cannot be tied to an individual and therefore fall outside data subject access and erasure requests. Our lawful basis for this limited processing is legitimate interest.

Pages inside your account — the chat, settings and administration areas — are excluded from website statistics entirely, clicks included.

4. Optional: the X (Twitter) pixel

We advertise on X and want to know whether those ads lead to sign-ups. For that we offer one optional technology, the X pixel, provided by Twitter International Unlimited Company (Ireland) and X Corp. (United States). It stays switched off until you press Accept in the banner; rejecting is just as easy and changes nothing about how summa works for you.

WhatPurposeDuration
X pixel script, loaded from static.ads-twitter.comReports visits to our public pages to X, so a sign-up can be attributed to an adOnly while you consent
_twclidFirst-party cookie holding the identifier of the X ad you clickedAs set by X
Cookies on X's own domainsSet and read by X under its own privacy policyAs set by X
Signup eventTells X that an account was created, identified only by a random account number — never your name, email address or conversationsSent once per account

Inside your account the pixel does not report page views; the only thing measured there is the signup event. You can change your answer at any time through Cookie settings in the website footer. Withdrawing removes the _twclid cookie and reloads the page without the pixel. We do not use session recording, heatmaps or any other advertising technology.

5. No third-party content

Apart from the X pixel, and only after you accept it, the website loads no third-party scripts, fonts, or content delivery networks. Typefaces are served from our own servers, so until then loading a page sends no request to any outside provider and no outside provider receives your IP address.

6. Browser controls

Blocking necessary cookies may prevent login or other essential functionality.